[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Full-disclosure] SSH brute force blocking tool



On Tue, Nov 28, 2006 at 10:56:33AM -0500, J. Oquendo wrote:
> Incorrect did you look at the fix? It isn't unsanitized as you state:

J, you have made an attempt to fix it, but is is not sufficient.

An attacker can still add arbitrary hosts to the deny list.

Thanks, Tavis.

-- 
-------------------------------------
taviso@xxxxxxxxxxxxxxxx | finger me for my pgp key.
-------------------------------------------------------

Attachment: pgpmW3kXxkg7V.pgp
Description: PGP signature

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/